logo

WSL in the Malware Ecosystem, (Wed, Feb 11th)

ID: 7f804689-2cd6-59c1-9a97-f19756662de7

STIX ID: report--7f804689-2cd6-59c1-9a97-f19756662de7

Feed Name: SANS ISC Diary

Threat Score
60/100

Date Published: 2026-02-11

Date Updated: 2026-04-19

...
...

This report analyzes a Cryxos infostealer sample (ottercookie-socketScript-module-3.js, SHA256:f44c2169250f86c8b42ec74616eacb08310ccc81ca9612eb68d23dc8715d7370) that detects Windows Subsystem for Linux (WSL), retrieves the Windows username via cmd.exe and /mnt/c/Users, and adds the /mnt mount to its search priority to access host drives—demonstrating how WSL can be abused as a LOLBIN to exfiltrate data; the report includes code snippets and indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.